<html>
<head>
  <meta http-equiv="Content-Security-Policy" content="script-src 'self'; img-src 'self'; default-src 'none'; connect-src 'self'; manifest-src 'self';  referrer origin; object-src 'none'; frame-src 'self'"  />
</head>
<body>
<script src="CVE-2016-1682.js" type="text/javascript" async defer ></script>
</body>
</html>
